> For the complete documentation index, see [llms.txt](https://documentation.ocsinventory-ng.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.ocsinventory-ng.org/administrator-docs/server-setup/installation-methods/using-official-repositories.md).

# Using Official Repositories

## Database setup

{% stepper %}
{% step %}
Install **PostgreSQL**

```sh
sudo apt update
sudo apt install postgresql postgresql-contrib
```

Ensure PostgreSQL starts now and on boot:

```sh
sudo systemctl start postgresql
sudo systemctl enable postgresql
```

{% endstep %}

{% step %}

#### **Create database and user, and set up the required permissions:**

Replace credentials as needed. This example uses:

* **Username**: `ocsuser`
* **Password**: `ocsuser`
* **Database Name**: `ocsdb`

```sh
sudo -u postgres psql <<EOF
-- Create user and database
CREATE USER ocsuser WITH PASSWORD 'ocsuser';
CREATE DATABASE ocsdb;

-- Grant basic connect permission
GRANT ALL PRIVILEGES ON DATABASE ocsdb TO ocsuser;

-- Connect to the database to set default privileges
\c ocsdb

-- Allow the application user to create objects in the public schema
GRANT USAGE, CREATE ON SCHEMA public TO ocsuser;

-- Set default privileges for future tables, sequences, and functions
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO ocsuser;
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON SEQUENCES TO ocsuser;
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON FUNCTIONS TO ocsuser;
EOF
```

{% endstep %}

{% step %}

#### **Configure PostgreSQL for remote connections:**

Update `postgresql.conf` to listen for remote connections. \
Assuming PostgreSQL version **17**, modify the `listen_addresses` setting:

{% code overflow="wrap" %}

```sh
sudo sed -i "s/#listen_addresses = 'localhost'/listen_addresses = '*'/" /etc/postgresql/17/main/postgresql.conf
```

{% endcode %}

Add a client authentication rule. Allow remote connections for the `ocsuser` user and `ocsdb` database:

{% code overflow="wrap" %}

```sh
echo "host    ocsdb          ocsuser         0.0.0.0/0               scram-sha-256" | sudo tee -a /etc/postgresql/17/main/pg_hba.conf
```

{% endcode %}

Restart the PostgreSQL service to apply the configuration changes:

```sh
sudo systemctl restart postgresql
```

{% endstep %}

{% step %}

#### **Test the remote connection**

From a remote machine with `psql` installed, verify access:

* Replace `<remote-server-ip>` with your PostgreSQL server's IP address.
* Enter the password (`ocsuser`) when prompted.

```sh
psql -h <remote-server-ip> -U ocsuser -d ocsdb
```

{% endstep %}
{% endstepper %}

## OCS Inventory Setup

{% tabs %}
{% tab title="Using Debian repositories" %}
{% stepper %}
{% step %}

#### Add the OCS Inventory repository

Add the OCS Inventory repository. This imports the GPG key used to sign OCS Inventory packages and registers the APT repository.

Replace `<distribution_codename>` with your system’s codename.

Supported codenames:

* Debian: `bookworm`, `trixie`
* Ubuntu: `jammy`, `noble`, `plucky`

```sh
curl -fsSL https://deb-v3.ocsinventory-ng.org/repo-signing-key.gpg | sudo gpg --dearmor -o /etc/apt/trusted.gpg.d/ocs-archive-keyring.gpg
echo "deb https://deb-v3.ocsinventory-ng.org/ <distribution_codename> main" | sudo tee /etc/apt/sources.list.d/ocsinventory.list
sudo apt update
```

This installs:

* `/etc/apt/trusted.gpg.d/ocs-archive-keyring.gpg` - the public GPG key used to verify package signatures
* `/etc/apt/sources.list.d/ocsinventory.list` - the repository definition
  {% endstep %}

{% step %}

### Install the packages

```sh
sudo apt install ocsinventory-server
```

This pulls in both `ocsinventory-backend` and `ocsinventory-frontend` with matching versions.

> On installation, `ocsinventory-backend` creates a dedicated system user used to run the uWSGI worker process and own the application files. It also generates a Django `SECRET_KEY` automatically.
> {% endstep %}

{% step %}

### Configure the backend

Run the interactive configuration script. Set the database connection and frontend redirection URL. The script then applies database migrations.

```sh
sudo /usr/share/ocsinventory-backend/tools/configure-ocsinventory-backend.sh
```

{% hint style="warning" %}
The database (PostgreSQL or MySQL/MariaDB) must already exist and be reachable before running this script — it is not created automatically.
{% endhint %}

You will be prompted for:

* The database engine: PostgreSQL or MySQL/MariaDB.
* The database host, port, name, username, and password.
* The frontend URL used for login redirection: `FRONTEND_REDIRECT`.

The script installs the matching Python database driver and runs `manage.py migrate`.

The following example shows the database prompts:

{% code overflow="wrap" %}

```sh
dev@ocsbackend:/usr/share/ocsinventory-backend/tools$ sudo bash configure-ocsinventory-backend.sh 

=================================================
=                                               =
=      OCS Inventory Backend configuration      =
=                                               =
=================================================

Select the database engine:

[1] PostgreSQL
[2] MySQL | MariaDB

Database engine [1|2]: 1
Database engine configured for PostgreSQL
Try to install PostgreSQL python library
Requirement already satisfied: psycopg2-binary>=2.9.9 in /usr/lib/ocsinventory-backend/venv/lib/python3.12/site-packages (from -r /usr/share/ocsinventory-backend/requirements_psql.txt (line 1)) (2.9.10)
Which host is running database server ?: 192.168.1.10
On which port is running database server ?: 5432
What is the database name ?: ocsdb
What is the database user name ?: ocsuser
What is the database user password ?: ocsuser
Configuration completed !
Now, running database migrations...
Database migrations successfully applied !

For more information, look at /tmp/ocsinventory-backend-configuration.log for the database migrations logs.

===========================================================
=                                                         =
=      OCS Inventory Backend successfully configured      =
=                                                         =
===========================================================

```

{% endcode %}

After successful configuration:

* Database migrations will run automatically.
* Logs for the database migrations can be found at `/tmp/ocsinventory-backend-configuration.log`.
  {% endstep %}

{% step %}

### Configure domain names

By default, both vhosts use `server_name _;`. They answer any request, regardless of its `Host` header. Configure a distinct hostname for each component when they share a server.

Update `server_name` in each Nginx vhost. For example, use `ocsinventory-backend.com` for the API. Use `ocsinventory-frontend.com` for the web console.

```sh
sudo sed -i 's/server_name _;/server_name ocsinventory-backend.com;/' /etc/nginx/sites-available/ocsinventory-backend
sudo sed -i 's/server_name _;/server_name ocsinventory-frontend.com;/' /etc/nginx/sites-available/ocsinventory-frontend
sudo nginx -t
sudo systemctl restart nginx
```

When both components share a node, two catch-all vhosts conflict. Assign each component a distinct hostname.

Ensure both domains resolve to this server's IP address. Use DNS or `/etc/hosts`.

If you configure a backend domain, update the frontend API route. Edit `/usr/share/ocsinventory-frontend/config/config.json`:

```json
{
  "BACKEND_API_ROUTE": "http://ocsinventory-backend.com:8081/"
}
```

{% hint style="info" %}
`config.json` is a static file. The change applies on the next page load.
{% endhint %}
{% endstep %}

{% step %}

### Access the application

* **Frontend (web console):** `http://<server-ip-or-domain>/`
* **Backend (API):** `http://<server-ip-or-domain>:8081/`

A `401 Unauthorized` response at the backend API root is expected. It confirms the backend is reachable.
{% endstep %}

{% step %}

### Services installed

| Service                      | Description                                          | Port                                                                   |
| ---------------------------- | ---------------------------------------------------- | ---------------------------------------------------------------------- |
| `nginx`                      | Serves the frontend and reverse-proxies the backend. | 80 (frontend), 8081 (backend)                                          |
| `ocsinventory-backend-uwsgi` | Runs the Django backend through uWSGI.               | Unix socket: `/var/run/ocsinventory-backend/ocsinventory-backend.sock` |

Useful commands:

```sh
sudo systemctl status ocsinventory-backend-uwsgi
sudo journalctl -u ocsinventory-backend-uwsgi -n 50 --no-pager
sudo tail -n 50 /var/log/ocsinventory-backend/ocsinventory-backend.log
```

{% endstep %}

{% step %}

### Verify installation

To confirm the installation was successful:

* Log into the web console and verify the interface loads correctly.
* Connect an OCS agent to the server and verify data transmission.

Having trouble? Check our [Troubleshooting](/administrator-docs/server-setup/troubleshooting.md) section.
{% endstep %}
{% endstepper %}
{% endtab %}

{% tab title="Using RPM repositories" %}
{% stepper %}
{% step %}

#### Add the OCS Inventory repository

The `ocsinventory-release` package configures the YUM/DNF repository and imports the GPG key used to sign OCS Inventory packages.

```bash
sudo dnf install -y https://rpm-v3.ocsinventory-ng.org/rpm/ocsinventory-release-latest.[elX|fcXX].noarch.rpm
```

> Replace `elX` or `fcXX` with the version matching your operating system, from those supported by OCS Inventory:
>
> * **Enterprise Linux** (RHEL, Rocky, AlmaLinux): `el9`, `el10`
> * **Fedora**: `fc42`, `fc43`, `fc44`

This installs:

* `/etc/yum.repos.d/ocsinventory.repo` - the repository definition
* `/etc/pki/rpm-gpg/RPM-GPG-KEY-ocsinventory` - the public GPG key, imported automatically on install

The key is **not** imported at this point. DNF imports it automatically the first time a package is actually installed from the `ocsinventory` repository (see step 2), prompting you to confirm the key fingerprint unless `assumeyes` is set.
{% endstep %}

{% step %}

### Install the packages

```bash
sudo dnf install -y ocsinventory-server
```

This pulls in both `ocsinventory-backend` and `ocsinventory-frontend` with matching versions.

On this first install from the `ocsinventory` repository, DNF prompts you to confirm and import the GPG key. Once accepted, you can verify it was imported with:

```bash
rpm -qa gpg-pubkey* --qf '%{name}-%{version}-%{release} --> %{summary}\n' | grep -i ocsinventory
```

> On installation, `ocsinventory-backend` creates a dedicated system user `ocsbackend` (member of the `nginx` group) used to run the uWSGI worker process and own the application files, and generates a Django `SECRET_KEY` automatically.
> {% endstep %}

{% step %}

### Configure the backend

Run the interactive configuration script to set the database connection and the frontend redirection URL, then apply database migrations:

```bash
sudo /usr/share/ocsinventory-backend/tools/configure-ocsinventory-rhel.sh
```

You will be prompted for:

* the database engine (PostgreSQL or MySQL/MariaDB)
* the database host, port, name, username and password
* the frontend URL used for login redirection (`FRONTEND_REDIRECT`)

The script installs the matching Python database driver, runs `manage.py migrate`, and restarts `ocsinventory-backend-uwsgi` and `nginx`.

{% hint style="warning" %}
The database (PostgreSQL or MySQL/MariaDB) must already exist and be reachable before running this script — it is not created automatically.
{% endhint %}
{% endstep %}

{% step %}

### Configure domain names

By default both vhosts use `server_name _;`, meaning they answer any request regardless of the `Host` header. If you serve OCS Inventory under dedicated domains (e.g. `ocsinventory-backend.com` for the API and `ocsinventory-frontend.com` for the web console), update `server_name` in each vhost accordingly:

```bash
sudo sed -i 's/server_name _;/server_name ocsinventory-backend.com;/' /etc/nginx/conf.d/ocsinventory-backend.conf
sudo sed -i 's/server_name _;/server_name ocsinventory-frontend.com;/' /etc/nginx/conf.d/ocsinventory-frontend.conf
sudo nginx -t
sudo systemctl restart nginx
```

Note : When both components share a single node, each package registers an Nginx server block with server\_name \_;. Having two catch-all blocks on port 80 creates a conflict. You must assign a distinct hostname to each component.

Make sure both domains resolve (DNS or `/etc/hosts`) to this server's IP.

If you set a dedicated domain for the backend, update the frontend so it calls the API on that domain instead of the server's bare IP. Edit `/usr/share/ocsinventory-frontend/config/config.json`:

```json
{
  "BACKEND_API_ROUTE": "http://ocsinventory-backend.com:8081/"
}
```

{% hint style="info" %}
`config.json` is served as a static file, so no service restart is needed — the change takes effect on the next page load.
{% endhint %}
{% endstep %}

{% step %}

### Access the application

* **Frontend (web console):** `http://<server-ip-or-domain>/`
* **Backend (API):** `http://<server-ip-or-domain>:8081/`

A `401 Unauthorized` / "authentication credentials not provided" response on the backend API root is expected and confirms the backend is reachable.
{% endstep %}

{% step %}

### Services installed

| Service                      | Description                                         | Port                                                                  |
| ---------------------------- | --------------------------------------------------- | --------------------------------------------------------------------- |
| `nginx`                      | Serves the frontend and reverse-proxies the backend | 80 (frontend), 8081 (backend)                                         |
| `ocsinventory-backend-uwsgi` | Runs the Django backend via uWSGI                   | unix socket `/var/run/ocsinventory-backend/ocsinventory-backend.sock` |

Useful commands:

```bash
sudo systemctl status ocsinventory-backend-uwsgi
sudo journalctl -u ocsinventory-backend-uwsgi -n 50 --no-pager
sudo tail -n 50 /var/log/ocsinventory-backend/ocsinventory-backend.log
```

{% endstep %}

{% step %}

### Verify installation

To confirm the installation was successful:

* Log into the web console and verify the interface loads correctly.
* Connect an OCS agent to the server and verify data transmission.

Having trouble? Check our [Troubleshooting](/administrator-docs/server-setup/troubleshooting.md) section.
{% endstep %}
{% endstepper %}
{% endtab %}
{% endtabs %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://documentation.ocsinventory-ng.org/administrator-docs/server-setup/installation-methods/using-official-repositories.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
